Western Sydney University statement on cyber incident

Western Sydney University has today notified individuals impacted by unauthorised access to its IT network.

The intrusion was identified by the University in January 2024 and quickly shut down, an investigation commenced and remediation measures were implemented.

Since January 2024, the University undertook its due diligence to understand the nature, scope and scale of the incident, the number of individuals impacted, and to protect against further harm. This was also done in accordance with the University’s legal obligations.

The investigation has indicated that the earliest known unauthorised access to the University’s Microsoft Office 365 environment was on 17 May 2023 and included access to some email accounts and SharePoint files.

Investigations also indicate that the University’s Solar Car Laboratory infrastructure may have been used as part of the incident.

Monitoring and scanning indicates that the preventative measures taken as a part of the incident response have successfully prevented any further unauthorised access.

The University is working with a range of authorities, including NSW Police whose investigation is ongoing. The University has also been in ongoing contact and working closely with the NSW Information and Privacy Commission.

We are now in a position to notify impacted individuals. Overall, approximately 7,500 individuals have received notifications from today. If you are among those affected being contacted today, you will have received an official notification from the University either by telephone call, email, or both.

The University is continuing to investigate the incident and if further persons are affected by the unauthorised access to the University IT network, they will be notified.

Importantly, there have been no threats received by the University to disclose any of the private information which was accessed, and the University has not received any demands in exchange for maintaining privacy.

In order to protect University staff, students and stakeholders, the University has sought and been granted an injunction from the NSW Supreme Court to prevent access, use, transmission and publication of any data that was the subject of the incident.

Interim Vice-Chancellor, Professor Clare Pollock, said: “On behalf of the University, I unreservedly apologise for this incident and its impact on our community. It is deeply regrettable, and we are committed to transparently rectifying the matter and fulfilling our obligations.”

“We appreciate that this may be upsetting, and we are here to support you as we work through this together. We have established a dedicated phone line and website to answer any questions you might have,” Professor Pollock said.

These channels are as follows:

As there are ongoing investigations and the matter is subject to court proceedings, the University is unable to comment any further at this point.

We thank you for your support.

ENDS

21 May 2024

Media Unit.

Latest News

ABC RN transcript: Vice-Chancellor Professor George Williams discusses higher education sector, student support, and the impact of AI

The following is a transcript of an interview that aired on ABC Radio National Saturday Extra between presenter, Nick Bryant and Vice-Chancellor, Distinguished Professor George Williams AO.

Western Sydney University are the number one Australian solar car team at the 2025 Bridgestone World Solar Challenge

Western Sydney Solar Car team has crossed the finish line placing preliminarily sixth in the world overall, and the number one Australian team in the world’s most prestigious solar car challenge.

Western Sydney University Statement on Cyber Incidents

Western Sydney University has issued an update to its community following confirmation that previously stolen personal information was published online, including on the dark web.